The U.S. government is warning that Iranian state-backed hackers are actively breaking in and disrupting industrial control systems at American water and energy providers. This new alert comes months after federal agencies warned of an escalation in hacking from Iranian actors amid the ongoing war.

In an advisory updated Wednesday, the FBI, the NSA, the Department of Energy, and CISA said Iranian hackers were targeting programmable logic controllers on internet-connected operational networks, allowing them to manipulate data on their displays, causing outages and disruption.

The Iranian hackers were initially discovered earlier this year to be targeting controllers made by Rockwell, but the advisory has now expanded the types of industrial control systems under attack to include products from Schneider Electric and Siemens.

The agencies warn that “potentially all internet exposed” industrial control systems may be affected, and urged critical infrastructure owners to take action. Per the advisory, the Iranian-backed hackers were “conducting this activity to cause disruptive effects within the United States,” likely in response to the ongoing war between Iran, and the U.S. and Israel.

According to the FBI, the hackers broke into one critical infrastructure provider and changed the controllers’ programming logic to disabled processes that handled critical shutdowns and alarms. The feds said this allowed “systems to enter unsafe conditions without notifying operators of the anomalies.”

This is the latest in a series of cyberattacks launched by Iranian government hackers and their proxies across the region since the start of the war in February. 

The hacks have ranged from the country’s typical espionage and hack-and-leak operations, such as leaking the contents of the FBI director Kash Patel’s personal email account, to more atypical destructive hacks that have caused large-scale damage or disruption. Among the more notable incidents was a hack on the U.S. medical tech giant Stryker, which allowed the Iranian hacking group “Handala” to remotely wipe tens of thousands of employee devices.

Handala also took credit for a data breach affecting California water provider Cal Water in June, and claimed it could have disrupted the water supply (without providing evidence). The water provider said that it saw no evidence of unauthorized access to its operational networks, which control the water supplies.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.



Source link

Share.
Leave A Reply

Exit mobile version